Cross-Origin Scripting Engine for Secure Application Collaboration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing access to network resources and monitoring for potential misuse across diverse client devices and network applications from different origins is challenging due to differences in access methods and security policies, limiting collaboration and integration between applications from different entities and servers.
Innovation Solution
A client application executes an application script within an embedded browser, establishing a domain of trust to enable cross-application collaboration by overriding same-origin policies, allowing data transfer and policy implementation across network applications from different entities and origins, using a scripting engine to generate scripts that meet security policies of various applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If same-origin policies are enforced to maintain security, then security is improved, but collaboration and integration between network applications from different origins deteriorate
Solution Approach 1:
The patent introduces an intermediary component (the client application with scripting engine) that mediates between network applications from different origins. This intermediary establishes a domain of trust and executes application scripts that enable cross-origin collaboration while maintaining security boundaries, thus resolving the contradiction between security enforcement and application interoperability
2Ease of operation
If access methods are standardized across client devices, then ease of management is improved, but adaptability to different client devices and access conditions deteriorates
Solution Approach 1:
The patent implements a universal access method where the client application with embedded browser and scripting engine can operate across diverse client devices (mobile phones, tablets, laptops, desktops) with different operating systems and browsers. The application scripts provide multi-functional capabilities to handle various access conditions and device types uniformly, thus achieving both ease of management and device adaptability
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Embodiments described include systems and methods for executing in an embedded browser an application script for network applications of different origins. A client application can establish a first session with a first network application of a first entity at a first origin via an embedded browser within the client application and a second session with a second network application of a second entity at a second origin via the embedded browser within the client application. A scripting engine within the client application of a client device of a user at a third origin can identify an application script having instructions to interact with the first network application and the second network application, and can execute the instructions to perform a task across the first network application of the first entity at the first origin and the second network application of the second entity at the second origin.